Decentralized Identity Management for Secure Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security protection schemes are centralized, making them vulnerable to illegal user intrusion and compromising data security.
Innovation Solution
A method for data acquisition in an alliance chain that involves acquiring a data calling request, performing identity authentication, assigning a decentralized identity, querying a data authorization certificate, sending a data authorization request, and encrypting the response, thereby enhancing data security through decentralized identity management and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized big data center platform is used for data access management, then data access can be authorized and controlled, but the system becomes vulnerable to illegal user intrusion and compromises data security
Solution Approach 1:
The patent segments the centralized data access control into distributed components. Each user obtains a decentralized identity token independently, and data authorization is distributed across multiple blockchain nodes rather than controlled by a single central platform. This segmentation eliminates the single point of failure and prevents illegal intrusion into the centralized system.
Solution Approach 2:
The patent introduces blockchain technology as an intermediary between data owners and data users. The blockchain serves as a trustless mediator that verifies identities and authorizations without requiring users to trust a central authority. The decentralized identity tokens act as intermediaries that carry user credentials securely without exposing sensitive information.
2Reliability
If decentralized identity management is implemented, then data security and intrusion prevention are improved, but the system complexity increases with multiple authentication steps
Solution Approach 1:
The patent performs preliminary actions by pre-generating and distributing decentralized identity tokens to users before actual data access is needed. Users register their identities and receive tokens in advance, so that during actual data access requests, the system only needs to verify the pre-issued tokens rather than performing complex authentication from scratch. This reduces the complexity of real-time authentication.
Solution Approach 2:
The patent creates copies of user identity information in the form of decentralized identity tokens that can be independently verified. Instead of storing master user databases centrally, the system maintains distributed copies of verified identity information across blockchain nodes. This allows multiple authentication steps to be simplified into token verification operations.
3Reliability
If multiple authentication and authorization steps are performed, then user security is enhanced, but the data acquisition process becomes more time-consuming
Solution Approach 1:
The patent ensures continuity of useful action by maintaining always-valid decentralized identity tokens that do not require repeated authentication. Once a user obtains a valid token, they can access authorized data multiple times without re-authenticating. The blockchain verification process continues to operate continuously in the background, ensuring security without interrupting the data acquisition workflow.
Solution Approach 2:
The patent implements feedback mechanisms where the blockchain network continuously verifies the validity of identity tokens and authorization permissions. The system provides immediate feedback on whether a token is valid and whether the user is authorized for the specific data access request. This rapid feedback loop minimizes verification time while maintaining high security standards.
Data Source
AI summary
Disclosed are a method and an apparatus for data acquisition, a device and a storage medium. The method includes: acquiring a data calling request sent by a first terminal; performing identity authentication to the data calling user corresponding to the first terminal according to the data calling request; assigning a second decentralized identity to the data calling user when the data calling user is authenticated legal; querying a data authorization certificate of the data authorization user by using the first decentralized identity according to the second decentralized identity; sending a data authorization request to a second terminal corresponding to the data authorization user according to the data authorization certificate; encrypting the request result corresponding to the data calling request after confirming that the data authorization user confirms the authorization, and sending the encrypted request result to the first terminal.


